General Terms and Conditions of Sale and Service -- SYAGA Audit
Effective date: 25 June 2026
Reference of the text displayed: Terms of Use - SYAGA Audit · en · SHA-256 340ea16343b72e44
This digital fingerprint identifies the text below down to a single character: it changes as soon as any clause changes. Save or print this page if you want to be able to establish later which text you read.
Article 1 -- Identification of the publisher
The SYAGA Audit service (available at syaga.eu) is published and operated by:
SYAGA CONSULTING, a limited liability company (EURL) with share capital of 20,000 euros, registered with the Aix-en-Provence Trade and Companies Register under SIREN number 518 489 471, incorporated on 08/12/2009.
Intra-EU VAT number: FR93 518489471.
Registered office: 2 Impasse Paul Langevin, 13110 Port-de-Bouc, France.
Manager: Sébastien Questier.
Contact: contact@syaga.eu.
Hereinafter referred to as the Publisher or the Provider. The professional customer subscribing to the service is referred to as the Customer. The Publisher and the Customer are together referred to as the Parties.
Article 2 -- Purpose and scope
These General Terms of Sale and Service (GTS) set out the conditions under which the Publisher provides the Client with access to the SYAGA Audit service and the associated services.
These Terms of Sale apply to any order placed by the Client and prevail over any other document, save for specific terms signed between the Parties (which take precedence in the event of any conflict with the present Terms). The service is intended exclusively for professional Clients acting within the scope of their business activity (B2B relationship); it is not offered to consumers within the meaning of the French Consumer Code.
Subscribing to the service, in any form whatsoever (online form, electronic acceptance, payment), constitutes full and unreserved acceptance of these Terms and Conditions of Sale.
Article 3 -- Definitions
- Service: the SYAGA Audit platform, accessible online, enabling the read-only compliance and security audit of a Microsoft 365 environment.
- Tenant: the Client's Microsoft 365 environment, as configured within Microsoft.
- Audit report: the structured document produced by the Service following the analysis of the Tenant.
- Free Offer (Free Score): limited, no-commitment access, providing an indicative compliance score without a full detailed report or access to Pro features.
- Pro Offer: full access to the Service, including the detailed report, exports and advanced features, subject to payment as set out in Article 5.
- Microsoft OAuth: the standard authorisation protocol used to allow the Service to access, on a read-only basis and with the Client's consent, the Tenant's configuration data via the Microsoft APIs (Microsoft Graph).
- Ephemeral architecture: the audit runs in memory inside a disposable scan container (no disk storage). The Report is delivered to the Client, who downloads it and then ticks the discharge box: that action triggers deletion of the data on the server side. Failing discharge, deletion is automatic no later than 2 hours after the end of the scan (24 hours for information supplied by the Client itself: company profile, declarative questionnaire). The Microsoft session token is encrypted at rest (Fernet) and its lifetime does not exceed 58 minutes; the technical token used during the scan expires no later than 3 hours after it is issued. The Client may revoke access at any time from its Microsoft Enterprise Applications.
Article 4 -- Description of the SYAGA Audit service
SYAGA Audit is a service for auditing the security and compliance of Microsoft 365 environments, carried out in read-only mode. The Service makes no changes to the configuration, data or settings of the Client's Tenant.
The service consists of:
- collect, on a read-only basis and via the Microsoft APIs authorised by the Customer through the Microsoft OAuth flow, configuration and security posture data from the Tenant;
- analyse this data against public best-practice frameworks (including, by way of indication and without limitation: ANSSI recommendations, the principles of Regulation (EU) 2016/679 GDPR, the requirements of Directive (EU) 2022/2555 NIS2);
- provide the Client with an audit Report accessible online, together with exports according to the offer subscribed to.
The Service operates on an ephemeral architecture: no Tenant configuration data is retained on the server side after the Report is delivered. Only the Client's billing data is retained (see Article 11).
4.1 Free Offer (Free Score)
The Publisher offers free access enabling users to obtain an indicative compliance score covering a limited scope of controls. This access is provided without any service-level guarantee and may be modified or discontinued by the Publisher at any time, without notice or compensation. It does not give rise to any invoice.
4.2 Pro Offer
The Pro Offer, subject to the payment set out in Article 5, grants access to the full audit report, the exports, the detailed recommendations and the advanced features described on the syaga.eu website.
The precise scope of the checks and the frameworks covered are described in the Service documentation. Coverage of the controls is not guaranteed to be exhaustive (see Article 10).
4.3 Usage limitations
The Publisher applies a cap of 2 audits per day per tenant to protect against abuse and technical overload. Any attempt to circumvent this limit constitutes a breach of these GTS.
Article 5 -- Price, VAT and payment
5.1 Pro Offer pricing. The price of the Pro Offer is set at 499 euros excluding tax (excl. VAT) per audit (one-off payment). This price is displayed excluding tax on the syaga.eu website.
5.2 VAT. Value added tax (VAT) at a rate of 20% is added to the price excluding VAT for Clients established in France, bringing the price including VAT to EUR 598.80 incl. VAT. For VAT-registered Clients established in another Member State of the European Union, the reverse-charge mechanism may apply. VAT is applied in accordance with the regulations: 20% in France, reverse charge for businesses established in the European Union holding a valid VAT number.
5.3 Payment method. Payment is made by bank card via the secure payment provider Stripe, at the time of the order (payment in full). Payment data is processed directly by Stripe; the Publisher does not retain the Client's bank details. An invoice is issued and sent to the Client after payment is received.
5.4 Price changes. The Publisher reserves the right to amend its prices. Any change is communicated to the Client before it takes effect. It has no bearing on orders already paid for.
5.5 Late-payment penalties (B2B). In accordance with Articles L. 441-10 et seq. of the French Commercial Code, any late payment between professionals automatically triggers the application of late-payment penalties at the statutory rate in force, together with the statutory fixed indemnity for recovery costs of 40 euros.
Article 6 -- Access to the service and Microsoft OAuth connection
Access to the Service requires the Client to have an active Microsoft 365 environment and to consent, via the standard Microsoft OAuth flow, to the granting of the permissions required for the audit, in accordance with the principle of least privilege (the narrowest permissions offered by Microsoft for each scope). This consent may be revoked at any time from the Client's Azure Active Directory / Entra ID portal.
The Publisher stores neither the Client's Microsoft credentials nor their password. The OAuth access token provided by Microsoft is encrypted at rest (Fernet) and used only for the duration of the audit. It is purged once the Report is delivered. The Client is responsible for the permissions they grant and may revoke them at any time.
Article 7 -- Delivery
The deliverables of the SYAGA Audit service are:
- an Audit Report accessible online on the Publisher's platform;
- exports of the report in the formats available under the offer subscribed to.
Delivery is deemed to have taken place when the Report is made available online to the Customer. Audit completion times are indicative and depend in particular on the availability of the access provided by the Customer and on the load on the systems.
Article 8 -- Term and termination
8.1 One-off service (Pro Offer, single payment). The service ends upon delivery of the Report and expiry of the access period associated with the audit carried out, without any formality.
8.2 Termination for breach. In the event of a serious breach by one of the Parties that is not remedied within thirty (30) calendar days of an unsuccessful formal notice, the other Party may terminate the contract automatically, without prejudice to any damages.
8.3 Effects of contract termination. When the contract ends, access to the Service is suspended. The handling of the Client's data is governed by the DPA available at dpa.html.
Article 9 -- Obligations of the Parties
9.1 Publisher's obligations. The Publisher undertakes to provide the Service diligently, in accordance with professional standards and in read-only mode, and to implement appropriate technical and organisational measures for the security of the data processed, in accordance with Article 32 of the GDPR.
9.2 Client's obligations. The Client undertakes to:
- provide the access and authorisations required to carry out the audit, and have the legal power to grant them;
- guarantee the accuracy of the information provided;
- use the Service in accordance with its purpose and with applicable regulations;
- not to undermine the security or integrity of the Service.
The Client remains solely responsible for the effective implementation of the recommendations set out in the audit Report.
Article 10 -- Liability and limitations
10.1 Nature of the service. The SYAGA Audit Service is an aid to the assessment and documentation of the Client's security and compliance posture. It constitutes neither a guarantee of regulatory compliance nor a guarantee of absolute security of the Client's Microsoft 365 environment. The Report reflects a state observed at a given moment, based on the data accessible in read-only mode. It does not replace an individualised legal analysis, a certification or an accreditation.
10.2 Best-efforts obligation. The Publisher is bound by a best-efforts obligation. It cannot be held liable for the consequences of a security breach, a non-compliance, an incident or a loss affecting the Client's environment.
10.3 Limitation of liability. To the extent permitted by the applicable law between professionals, the Publisher's total liability is limited to the amount of the sums actually paid by the Customer for the relevant service during the twelve (12) months preceding the triggering event. The Publisher is not liable for indirect damages (loss of business, loss of data, loss of turnover, damage to reputation). This clause is valid between professionals subject to the applicable rules of public policy.
10.4 Availability. The Publisher endeavours to ensure the availability of the Service. In the absence of a separate SLA appendix, no quantified availability commitment is guaranteed and the Service is provided as is, subject to mandatory legal obligations.
10.5 Force majeure. Neither Party may be held liable for a breach resulting from an event of force majeure within the meaning of Article 1218 of the French Civil Code.
Article 11 -- Protection of personal data
The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and amended Act No. 78-17 of 6 January 1978.
11.1 Roles. For the data collected in the Client's Tenant during the audit, the Publisher acts as a processor on behalf of the Client (the controller) within the meaning of Article 28 of the GDPR. A Data Processing Agreement (DPA) governing this processing is available at dpa.html and is deemed accepted by the Client concurrently with these Terms and Conditions.
11.2 Account and billing data. For data collected directly from the Client (identity, email, billing), the Publisher acts as data controller, in accordance with its privacy policy available at confidentialite.html.
11.3 Ephemeral architecture and retention periods. The Tenant's configuration data (findings, access token) is deleted as soon as the Client ticks the discharge box on its Report, once it has downloaded its files. Failing discharge, deletion is automatic no later than 2 hours after the end of the scan, and no later than 24 hours after they are sent for information supplied by the Client itself (company profile, declarative questionnaire). Only the data strictly necessary for billing is retained durably, for 10 years from the close of the financial year, in accordance with legal obligations.
11.4 Cookies. The syaga.eu website uses only cookies strictly necessary for the operation of the Service (anti-bot security, session). No third-party advertising or analytics cookies are placed. These cookies are exempt from prior consent in accordance with the CNIL guidelines.
11.5 Hosting. Data is hosted in France, on the OVH (France) infrastructure operated for the Publisher (SYAGA CONSULTING).
Article 12 -- Intellectual property
The SYAGA Audit platform, its software components, its analysis and audit engine, its documentation, its methodologies, its trademarks and its content remain the exclusive property of the Publisher. No provision of these Terms of Sale entails any transfer of intellectual property rights to the Client.
The Client is granted a personal, non-exclusive and non-transferable right to use the Service and the Reports, for its internal needs, for the term of the contract. Report exports may be retained by the Client after the engagement for its own internal documentation needs. The Client's data (its Tenant data) remains its property.
Article 13 -- Right of withdrawal (B2B)
As the Service is intended exclusively for professional Clients acting in the course of their business (B2B relationship), the right of withdrawal provided by the Consumer Code for the benefit of consumers does not apply.
As the Client is acting in a professional capacity, the consumer protection provisions, including Article L.221-3 of the French Consumer Code, do not apply.
Warranty of proper operation (re-run, exceptional refund). SYAGA Consulting undertakes to deliver a functional audit and a usable report within the stated timeframe. In the event of difficulty, the Customer shall notify SYAGA Consulting by email at contact@syaga.eu within fourteen (14) days; SYAGA Consulting will, as a priority, re-run the audit and provide the necessary assistance until a compliant report is delivered. A refund is granted only on an exceptional basis and solely where it is objectively established, by tangible evidence, either (i) that the collection of data or the production of a usable report is impossible (for example a change to Microsoft's interfaces (APIs) preventing collection and resulting in a report devoid of content), or (ii) that the report could not be delivered within a timeframe manifestly excessive relative to the stated timeframe (the audit, normally completed within a few tens of minutes, failing to conclude after an unreasonable delay). Outside these objectively proven cases, since the service is performed and the report delivered, no refund is due; a mere change of mind or non-use of the report does not constitute grounds.
As the Pro Offer is a one-off payment for a one-time service, no refund is due once the Report has been delivered.
Article 14 -- Confidentiality
Each Party undertakes to keep confidential the non-public information exchanged under the contract, for its duration and for a period of three (3) years after its termination, except for information that has become public without any fault of the receiving Party.
Article 15 -- Governing law and competent jurisdiction
These Terms and Conditions are governed by French law.
In the event of a dispute, and failing prior amicable resolution within thirty (30) days of notification of the dispute, exclusive jurisdiction is granted to the courts within the jurisdiction of Aix-en-Provence, subject to the mandatory rules applicable to cross-border disputes.
Article 16 -- Miscellaneous provisions
If any provision of the GTC were declared void or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in force. Tolerance by one of the Parties of a breach by the other shall not constitute a waiver of its rights. The GTC constitute the entire agreement between the Parties on their subject matter and supersede any prior agreement.
Legal references
- Regulation (EU) 2016/679 (GDPR), Articles 13, 14, 28, 32: EUR-Lex CELEX:32016R0679
- Act No. 78-17 of 6 January 1978, as amended (French Data Protection Act): Légifrance
- Commercial Code, art. L.441-10 et seq. (B2B late-payment penalties): Légifrance
- French Civil Code, art. 1218 (force majeure)
- CNIL, cookie guidelines: cnil.fr